Nlnetlabs Unbound — CVE-2026-50252 (Critical)
Summary
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.3) in Nlnetlabs Unbound. Patch or mitigate promptly. EPSS percentile: 2%.
Operator check
Review CVE-2026-50252 in your asset inventory. Apply patches per vendor guidance and verify Unbound is not exposed. CVSS score: 9.3. EPSS probability: 0.1%; percentile: 2%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.